INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TanStack supply chain attack compromises OpenAI

| 2026-05-14 19:07 HIGH HIGH AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH SUPPLY CHAIN
Executive Summary
AI-generated
On May 14, 2026, a security breach occurred at OpenAI, where two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages. The attackers exploited weaknesses in GitHub Actions workflows to execute malicious code, extract tokens from memory, and publish malicious package versions through legitimate releases. This campaign is linked to the "Mini Shai-Hulud" supply-chain attack by the TeamPCP extortion gang, which targeted developers by slipping malicious updates into trusted software packages. As a precaution, OpenAI rotated its code-signing certificates for applications on macOS, Windows, iOS, and Android, with only limited credentials stolen from internal source code repositories. The company isolated affected systems and accounts, revoked sessions, and temporarily restricted deployment workflows, while conducting a forensic investigation with a third-party incident response firm.
Technical Mitigations AI-generated
• Rotate code-signing certificates for OpenAI applications on macOS to prevent potential launch or update issues due to Apple's notarization process. • Use a secure CI/CD configuration and GitHub Actions workflows to prevent abuse of weaknesses in project repositories, as seen in the TanStack supply chain attack. • Monitor for malicious package versions being published through legitimate releases by tracking changes in package tarballs and repository activity.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
IR IL RU
technologytechnology
Incident Timeline
‎2026/05/14
Threat actors used malicious updates to target developers by slipping malware into trusted software packages, resulting in unauthorized access and credential-focused exfiltration activity within OpenAI's internal source code repositories.
infrastructure Macos
infrastructure Windows
infrastructure Ios
infrastructure Android
‎June 12, 2026
Threat actors used the Mini Shai-Hulud malware to target hundreds of npm and PyPI packages, including those in the TanStack supply chain, with the goal of stealing developer credentials.
infrastructure Linux
infrastructure Windows
infrastructure Ios
infrastructure Vs Code
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Vs Code
Affected Product
Intelligence Sources
BleepingComputer 2026-05-14